finalize-pr

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches the visible workflow, but the skill enables bounded autonomous PR pushes and code-fixing based on external CI/review content, while delegating all sensitive actions to opaque sub-skills with unverifiable provenance from this file alone. No direct exfiltration or malicious mismatch is visible, but the hidden execution surface and autonomous write/push behavior make the overall risk medium.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/Codagent-AI%2Fagent-skills%2Ffinalize-pr%2F@31cfacb505e64da75acf0f32869e119611236043